Description
A Single-AZ RDS DB instance does not have Multi-AZ standby failover when the primary instance or its Availability Zone fails. For workloads that need higher availability, consider a Multi-AZ deployment with a standby instance in another zone.
Potential impact
Failures or maintenance can cause longer database outages, application errors and more manual recovery work.
Remediation
Set MultiAZ: true on supported RDS DB instances and assess costs and change impact. Test failover and application reconnection, and retain a backup and recovery plan. Multi-AZ does not guarantee uninterrupted service or replace backups. Aurora uses a separate cluster availability configuration.
Examples
These are RDS MySQL instance excerpts. Define a supported DBInstanceType and the remaining network settings. RDS is configured to manage the master password in Secrets Manager.
Before
Resources:
MasterDB:
Type: AWS::RDS::DBInstance
Properties:
DBName: MyDatabase
AllocatedStorage: "20"
DBInstanceClass: !Ref DBInstanceType
Engine: mysql
MasterUsername: admin
ManageMasterUserPassword: true
The new instance does not request Multi-AZ. Compare this with the workload’s tolerated downtime.
After
Resources:
MasterDB:
Type: AWS::RDS::DBInstance
Properties:
DBName: MyDatabase
AllocatedStorage: "20"
DBInstanceClass: !Ref DBInstanceType
Engine: mysql
MasterUsername: admin
ManageMasterUserPassword: true
MultiAZ: true
The instance can fail over to a standby in another Availability Zone. This DB instance’s standby replica does not serve read-scaling traffic.